Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c07471f6 by Salvatore Bonaccorso at 2026-08-21T21:47:43+02:00
Process some new NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,31 +7,31 @@ CVE-2026-9244
 CVE-2026-9012
        REJECTED
 CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested 
path with  ...)
-       TODO: check
+       NOT-FOR-US: zanllp infinite-image-browsing
 CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested 
path agai ...)
-       TODO: check
+       NOT-FOR-US: zanllp infinite-image-browsing
 CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) 
protocol mess ...)
        NOT-FOR-US: DJI
 CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 
5.6.2.  ...)
-       TODO: check
+       NOT-FOR-US: Dromara RuoYi-Vue-Plus
 CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the 
transaction sa ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the 
x-headroom-user ...)
-       TODO: check
+       NOT-FOR-US: Headroom's LLM proxy
 CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream 
destination wit ...)
-       TODO: check
+       NOT-FOR-US: Headroom's LLM proxy
 CVE-2026-77769 (The report.list procedure in 
packages/trpc/src/routers/report.ts accep ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-77768 (The report.get procedure in 
packages/trpc/src/routers/report.ts accept ...)
-       TODO: check
+       NOT-FOR-US: OpenPanel
 CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in 
apps/api/app ...)
-       TODO: check
+       NOT-FOR-US: Reconmap
 CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// 
stores a ...)
        TODO: check
 CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could 
cause data f ...)
        TODO: check
 CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the 
transaction AP ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix 
when pro ...)
        TODO: check
 CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP 
object  ...)
@@ -41,9 +41,9 @@ CVE-2026-77710 (A vulnerability in misp-stix could allow a 
crafted STIX document
 CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This 
affects  ...)
        NOT-FOR-US: Dolibarr
 CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 
2.6.0.1. Affect ...)
-       TODO: check
+       NOT-FOR-US: Comfast
 CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 
1.0. Aff ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro Online Job Portal
 CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of 
malicious  ...)
        TODO: check
 CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution 
of mali ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to